PT-2007-6607 · Microsoft+1 · Windows Server 2003+5
Elia Florip
+3
·
Publicado
2007-10-19
·
Atualizado
2018-10-15
·
CVE-2007-5587
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP SP2
Microsoft Windows XP Professional x64
Microsoft Windows XP x64 SP2
Microsoft Windows Server 2003 SP1
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 x64
Microsoft Windows Server 2003 x64 SP2
secdrv.sys version prior to 4.3.86.0
Description
A buffer overflow issue exists in the Macrovision SafeDisc secdrv.sys driver, allowing local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD NEITHER IOCTL.
Recommendations
For Microsoft Windows XP SP2, update the secdrv.sys driver to version 4.3.86.0 or later.
For Microsoft Windows XP Professional x64, update the secdrv.sys driver to version 4.3.86.0 or later.
For Microsoft Windows XP x64 SP2, update the secdrv.sys driver to version 4.3.86.0 or later.
For Microsoft Windows Server 2003 SP1, update the secdrv.sys driver to version 4.3.86.0 or later.
For Microsoft Windows Server 2003 SP2, update the secdrv.sys driver to version 4.3.86.0 or later.
For Microsoft Windows Server 2003 x64, update the secdrv.sys driver to version 4.3.86.0 or later.
For Microsoft Windows Server 2003 x64 SP2, update the secdrv.sys driver to version 4.3.86.0 or later.
As a temporary workaround, consider restricting access to the secdrv.sys driver until a patch is available.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows Server 2003
Windows Server 2003 X64
Windows Xp
Windows Xp Professional X64
Windows Xp X64
Secdrv.Sys